HIGH🇵🇱 Wersja polska

CVE-2020-5724

CVSS 7.5v3.1pub. 2020-03-30upd. 2024-11-21

The Grandstream UCM6200 series before 1.0.20.22 is vulnerable to an SQL injection via the HTTP server's websockify endpoint. A remote unauthenticated attacker can invoke the challenge action with a crafted username and discover user passwords.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
  • Grandstream Ucm6202

    HW
    Grandstream
    all versions
  • Grandstream Ucm6202 Firmware

    OS
    Grandstream
    < 1.0.20.22
  • Grandstream Ucm6204

    HW
    Grandstream
    all versions
  • Grandstream Ucm6204 Firmware

    OS
    Grandstream
    < 1.0.20.22
  • Grandstream Ucm6208

    HW
    Grandstream
    all versions
  • Grandstream Ucm6208 Firmware

    OS
    Grandstream
    < 1.0.20.22
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
SQLiAuth Bypass
CWE
References

Related vulnerabilities

CVE-2020-5757CRITICAL9.8PL ✓same product

Command injection w Grandstream UCM6200 — wykonanie kodu jako root

CVE-2020-5759CRITICAL9.8PL ✓same product

Command Injection w Grandstream UCM6200 via SSH — wykonanie poleceń jako root

CVE-2020-5723CRITICAL9.8PL ✓same product

Grandstream UCM6200 — niezaszyfrowane hasła użytkowników w bazie SQLite

CVE-2020-5758HIGH8.8same product

Grandstream UCM6200 series firmware version 1.0.20.23 and below is vulnerable to OS command injection via HTTP...

CVE-2020-5726HIGH7.5same product

The Grandstream UCM6200 series before 1.0.20.22 is vulnerable to an SQL injection via the CTI server on port 8...